An issue exists in the ajax-bootmodal-login plugin 1.4.3 for WordPress. The register form, login form, and password-recovery form require solving a CAPTCHA to perform actions. However, this is required only once per user session, and therefore one could send as many requests as one wished by automation.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
ajax bootmodal login project ajax bootmodal login 1.4.3 |